Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signed files on PyPI #14624

Open
yan12125 opened this issue Oct 29, 2017 · 0 comments
Open

Signed files on PyPI #14624

yan12125 opened this issue Oct 29, 2017 · 0 comments
Labels

Comments

@yan12125
Copy link
Collaborator

@yan12125 yan12125 commented Oct 29, 2017

Make sure you are using the latest version: run youtube-dl --version and ensure your version is 2017.10.29. If it's not, read this FAQ entry and update. Issues with outdated version will be rejected.

  • I've verified and I assure that I'm running youtube-dl 2017.10.29

Before submitting an issue make sure you have:

  • At least skimmed through the README, most notably the FAQ and BUGS sections
  • Searched the bugtracker for similar issues including closed ones

What is the purpose of your issue?

  • Bug report (encountered problems with youtube-dl)
  • Site support request (request for adding support for a new site)
  • Feature request (request for a new functionality)
  • Question
  • Other

The following sections concretize particular purposed issues, you can erase any section (the contents between triple ---) not applicable to your issue


Description of your issue, suggested solution and other information

Currently files on PyPI are only verified via MD5 sums on pypi.python.org [1] or SHA256 sums on pypi.io [2]. I think it should be better to have those files signed. For example, numpy has detached pgp signatures for all files [3].

Technically it looks easy. Just an extra argument --sign in python setup.py upload [4] is enough.

[1] https://pypi.python.org/pypi/youtube_dl
[2] https://pypi.org/project/youtube_dl/#files
[3] https://pypi.python.org/pypi/numpy
[4] https://docs.python.org/3/distutils/packageindex.html#the-upload-command

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant
You can’t perform that action at this time.